Close Menu
arabianfeature.comarabianfeature.com
    What's Hot

    Kering loops France’s Ardian into Fifth Avenue investment

    December 16, 2025

    Dior, Rizzoli to release book on Lady Art project

    December 16, 2025

    Coty earns ‘A’ score from CDP

    December 16, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    arabianfeature.comarabianfeature.com
    Subscribe
    • Home
    • CEOs
    • Women
    • AI & Tech
    • Magazine
    • Real Estate
    • Luxury
    • Feature
    arabianfeature.comarabianfeature.com
    Home » Kaspersky warns of ChatGPT-themed macOS malware campaign
    Feature

    Kaspersky warns of ChatGPT-themed macOS malware campaign

    Arabian Media staffBy Arabian Media staffDecember 16, 2025No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    ChatGPT

    Image: Getty Images

    Kaspersky Threat Research has uncovered a new malware campaign targeting macOS users, exploiting paid Google search ads and shared conversations on the official ChatGPT website to distribute the AMOS (Atomic macOS Stealer) infostealer along with a persistent backdoor.

    According to Kaspersky, attackers are purchasing sponsored search ads linked to queries such as “chatgpt atlas” and redirecting users to what appears to be an installation guide for “ChatGPT Atlas for macOS”. The page is hosted on chatgpt.com and presented as a shared ChatGPT conversation. In reality, the content has been generated through prompt engineering and stripped down to display only step-by-step installation instructions.

    The guide instructs users to copy a single line of code, open the Terminal application on macOS, paste the command, and grant all requested permissions. Kaspersky’s analysis shows that executing the command downloads and runs a malicious script from an external domain, atlas-extension[.]com.

    The script repeatedly prompts users for their system password, validating it by attempting to execute system-level commands. Once the correct password is entered, the malware proceeds to download and install the AMOS infostealer using the stolen credentials, before launching it on the device. The infection method is a variation of the “ClickFix” technique, which relies on persuading users to manually execute shell commands that retrieve malicious code from remote servers.

    Once installed, AMOS harvests sensitive data that can be monetised or reused in subsequent attacks. This includes passwords and cookies from popular web browsers, data from cryptocurrency wallets such as Electrum, Coinomi and Exodus, and information from applications including Telegram Desktop and OpenVPN Connect. The malware also scans for TXT, PDF and DOCX files stored in Desktop, Documents and Downloads folders, as well as notes saved in the macOS Notes app, exfiltrating the data to attacker-controlled infrastructure.

    A backdoor

    In parallel, the campaign deploys a backdoor that is configured to persist across system reboots, providing attackers with remote access to compromised devices and duplicating much of AMOS’s data-collection functionality.

    Kaspersky said the campaign highlights a broader trend in which infostealers have emerged as one of the fastest-growing cyber threats in 2025. Attackers are increasingly leveraging AI-related themes, fake AI tools and AI-generated content to enhance the credibility of their lures. The Atlas-themed activity extends this trend by abusing a legitimate AI platform’s content-sharing features.

    Read: Inside Kaspersky’s plan to build cyber immune systems for the GCC

    “What makes this case effective is not a sophisticated exploit, but the way social engineering is wrapped in a familiar AI context,” said Vladimir Gursky, malware analyst at Kaspersky. “A sponsored link leads to a well-formatted page on a trusted domain, and the ‘installation guide’ is just a single Terminal command. For many users, that combination of trust and simplicity is enough to bypass their usual caution, yet the result is full compromise of the system and long-term access for the attacker.”

    Kaspersky advised users to exercise caution when encountering unsolicited guides that require running Terminal or PowerShell commands, particularly those involving one-line scripts copied from websites, documents or chat messages. The company also recommended verifying suspicious commands using security tools, avoiding unclear instructions, and ensuring reputable security software is installed and kept up to date on macOS systems.






    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleAddress Downtown debuts Dubai digital hotel check-in
    Next Article Pioneering a financial model for full user control
    Arabian Media staff
    • Website

    Related Posts

    UAE faces days of rain, strong winds

    December 16, 2025

    Pioneering a financial model for full user control

    December 16, 2025

    Address Downtown debuts Dubai digital hotel check-in

    December 16, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    10 Trends From Year 2020 That Predict Business Apps Popularity

    January 20, 2021

    Shipping Lines Continue to Increase Fees, Firms Face More Difficulties

    January 15, 2021

    Qatar Airways Helps Bring Tens of Thousands of Seafarers

    January 15, 2021

    Subscribe to Updates

    Get the best of Arab culture, lifestyle, and stories . Straight to your inbox. Subscribe to Arabian Feature and never miss a beat.

    Arabian Feature is your window into the heart of the Arab world. We bring you inspiring stories, fresh perspectives, and unique voices from across the region—covering culture, lifestyle, people, and progress. Bold, curious, and proudly Arab.

    Facebook X (Twitter) Instagram Pinterest YouTube
    Top Insights

    Top UK Stocks to Watch: Capita Shares Rise as it Unveils

    January 15, 2021
    8.5

    Digital Euro Might Suck Away 8% of Banks’ Deposits

    January 12, 2021

    Oil Gains on OPEC Outlook That U.S. Growth Will Slow

    January 11, 2021
    Get Informed

    Subscribe to Updates

    Get the best of Arab culture, lifestyle, and stories . Straight to your inbox. Subscribe to Arabian Feature and never miss a beat.

    @2025 copyright by Arabian Media Group
    • Home
    • About Us

    Type above and press Enter to search. Press Esc to cancel.